CAA record Propagation Checker

See whether your CAA record change has spread: 12 public resolvers, queried live, side by side.

Map key: each dot is the country where a resolver's operator is headquartered (number = resolvers), coloured by result. It does not show where the query ran — most of these resolvers are anycast networks with servers in many cities.

Reading the results

  • ✓ green — the resolver returned a record
  • ✕ red — no record / no answer
  • Different answers = still propagating; wait for the old TTL to expire

What this is — and isn't

These are 12 large public resolvers, queried live over encrypted DNS-over-HTTPS from our servers. Most are anycast networks with many locations, so we show which resolver answered — not a city. Two (CIRA Canadian Shield) are run by the organization that operates .ca. Your ISP's resolver may still show an older answer until its cache expires.

What is an CAA record?

CAA records declare which certificate authorities (for example Let's Encrypt) are allowed to issue SSL certificates for your domain. Publishing a wrong CAA record can stop certificate issuance or renewal.

How to check CAA record propagation

Type your domain in the box above, keep CAA selected and press Search. We ask 12 public DNS resolvers — including two run by CIRA Canadian Shield — at the same moment and show each answer side by side.

Reading the results

Green rows should show your CAA entries (for example 0 issue "letsencrypt.org"). "No CAA record" is also valid — it means any CA may issue. Before requesting a certificate, make sure the CA you use appears on every row.

Common problems

Related DNS tools

A propagationCheck A record on 12 resolversAAAA propagationCheck AAAA record on 12 resolversCNAME propagationCheck CNAME record on 12 resolversMX propagationCheck MX record on 12 resolversNS propagationCheck NS record (nameserver) on 12 resolversTXT propagationCheck TXT record on 12 resolversSOA propagationCheck SOA record on 12 resolversCAA propagationCheck CAA record on 12 resolversDNS in CanadaCanadian ISPs and CIRA resolversMain checkerAll record types

Frequently asked questions

Do I need a CAA record?

No, but it is a good security practice and some hosts add one automatically.

Why did my SSL certificate fail after a CAA change?

The issuing CA is probably not allowed in the CAA record, or the change has not propagated to the CA yet.

How long does CAA propagation take?

Governed by the TTL of the previous CAA record.